Who we are
NCRepairBench repairs computers, phones and game consoles and does logical data recovery for Greensboro, Winston-Salem and High Point. One person runs it, and that person is the only one with access to the records described below. You can reach us at [email protected]. We are based in High Point, NC 27265.
What we collect
When you send a repair request
- Your name, phone number and email address, so we can reach you about the repair.
- The device type and, if you give it, the make and model.
- How you want to get it to us (mail-in, drop-off or house call).
- Your description of the problem.
- An optional device passcode. Only if you choose to give one. See Device passcodes below for how it is handled.
- Technical data recorded with the request: a keyed one-way hash of your IP address (we cannot turn the hash back into the address), your browser's user agent string, the page that sent you to the form (the referrer), the time it was sent, and a spam score the server works out. When the Cloudflare Turnstile check is switched on, we also record whether it passed.
When you email us
- Your email address, the name shown on your message, the subject, and the plain text of the message. If your mail client sent an HTML version as well, we keep only the plain text.
- The threading headers a mail client uses to keep a reply under the right message.
- The names, types and sizes of any attachments. The files themselves are not stored in our database. The original message, attachments included, is forwarded to the owner's mailbox by Cloudflare Email Routing (see Services we rely on).
- The SPF and DKIM results reported by Cloudflare, which tell the owner whether the message really came from the address it claims.
When you check on a repair
The ticket number and email address you type in are used to find the matching record and for nothing else. Failed lookups are counted against the hashed IP address so the page cannot be used to guess ticket numbers.
When you just browse
The server keeps short-lived rate-limit counters keyed by the hashed IP address. When a limit is hit, the abuse log records the hashed address, the user agent, the path requested and whether the request was blocked. There is no analytics script, no tracking pixel and no advertising code on any page.
What we do not collect
No payment details. There is no card field anywhere on this site and no payment processor behind it. There are no customer accounts or logins. We do not ask for your location beyond what you type into the form or into an email.
Why we collect it
- To do the repair and keep in touch about it: to send you a quote, ask a question, and tell you when the device is ready.
- To match a mailed-in or dropped-off device to the request that came with it.
- To keep a record of what was done on each job, which is what the ticket number and the status timeline are.
- To keep the form and the status page from being abused by bots and scripts. That is what the hashed IP address, the user agent and the spam score are for.
We do not use anything you give us for marketing. There is no mailing list and no newsletter, and nothing is sold or passed to anyone else for their marketing.
Device passcodes
The repair form has an optional field for a device passcode or unlock code. We ask because a locked phone or laptop cannot be fully tested: without getting past the lock screen we cannot check the screen, the cameras, the speakers, the ports or whether the fault is really fixed. You do not have to give one. If you leave it blank we test what we can from the outside and say so on the quote.
If you do give one, this is what happens to it:
- It is encrypted at rest with AES-256-GCM, with a fresh random nonce for each record, under a key that is kept outside the database. It is never written down in plain text.
- It never appears in a list of requests, in a spreadsheet export, in a notification or in a log line.
- The owner can reveal it in the admin dashboard only when working on the device, and every reveal is logged: who, when, which ticket and why. That log entry does not contain the passcode.
- It is deleted automatically 30 days after the job closes. You can ask us to delete it sooner at any time.
If you would rather not share your everyday passcode, set a temporary one for the duration of the repair and change it back afterwards. That is a sensible habit with any repair shop, including this one.
How long we keep it
- Repair requests: 365 days after they were filed. After that the personal fields are blanked: your name, phone number, email address, model, problem description, passcode, user agent and referrer. The ticket number, the device type, the status and the dates stay, so there is still a record that a job happened and what stage it reached. A redacted request can no longer be looked up on the Check Status page, because the email address it was matched on is gone.
- Device passcodes: 30 days after the job closes, or sooner on request.
- The abuse and rate-limit log: 90 days.
- The audit log of the owner's actions in the dashboard: 365 days.
- The owner's admin sign-in session: at most 12 hours.
- Email conversations: kept so a thread can be picked up later if you come back with the same device or a new one. Deleted when you ask (see Your choices).
A backup of the database holds whatever the database held when the backup was taken. Backups are treated as confidential in exactly the same way as the live copy.
Who can see it
The owner, and nobody else. There are no employees, no contractors and no outside support staff with access to the dashboard or the database.
We do not sell, rent or share your information. The only times any of it leaves the shop are these:
- Your name and address go on the shipping label when a mail-in device is sent back to you, which means the carrier sees them.
- The services listed in the next section handle it as part of running the site, the form and the email.
- If the law requires it.
Services we rely on and what each one receives
- Cloudflare. The site sits behind Cloudflare's network, so every page request passes through it and Cloudflare sees your IP address and the pages you ask for, the way any web host would. When the Turnstile check on the repair form is switched on, Cloudflare runs its bot check in your browser and receives whatever signals it needs for that; we receive only a pass or fail. Cloudflare Email Routing receives every message sent to [email protected], forwards the original to the owner's mailbox and passes a copy to our server so it can be stored with your repair.
- Resend. When we reply to an email from our system, Resend delivers it. It handles your email address, the subject line and the text of that reply.
- Discord. The owner reads notifications on a phone through a private Discord channel. A new repair request produces a short notice carrying the ticket number, your first name, the device type, the method and the first line of your problem description. It never carries the passcode, your phone number or your email address. Emails you send to us are also posted into a private Discord thread, message text included, so the owner can read and answer them from a phone. Discord's servers therefore hold a copy of those messages.
Each of those companies has its own privacy policy that covers what it does with the data on its side.
Cookies
This site sets one cookie, and only for the owner: it holds the sign-in session for the admin area. Visitors get no cookie from us. There is no analytics, no advertising and no tracking of any kind. Cloudflare's network, and the Turnstile check when it is on, may set cookies of their own for bot protection; we do not read them and they are not used for advertising.
Email is how the shop talks to customers. Messages in both directions are stored and, where there is a matching repair, attached to that ticket, so the whole history of a job is in one place and a question you asked in March still makes sense in June. Replies from us come from [email protected] whether the owner typed them in the dashboard or in the Discord thread.
Security
The site is served over HTTPS. Passcodes are encrypted, IP addresses are stored only as keyed hashes, the admin area is behind a password with lockout on repeated failures, and every action in the dashboard that changes customer data is logged. No system is perfectly secure. If something happened that put your information at risk, we would tell you at the email address on your request.
Your choices
- See, correct or delete what we hold. Email [email protected] from the address you used on the request and quote the ticket number if you have it. We will confirm what is there and fix or remove it.
- Deletion redacts rather than erases the ticket. Your personal details are blanked the same way the 365-day sweep does it. The ticket number, device type, status and dates stay as the business record of the job.
- Delete the passcode early. Ask, and it goes straight away rather than at the 30-day mark.
- Do not give a passcode at all. The field is optional. The trade-off is explained in the terms.
Children
This site is not directed at children under 13 and we do not knowingly collect information from them. A child's device is welcome; the request should come from a parent or guardian. If you believe a child has sent us their details, email us and we will remove them.
Changes to this policy
If this page changes, the date at the top changes with it. If a change affects what we collect or who can see it, we will say so here rather than quietly rewording it.
Contact
Questions about any of this go to [email protected]. NCRepairBench, High Point, NC 27265.